I understand your question, but you do need to take into account the added security risks when more detailed information is available for failed authentication.
If an attacker gets the message that the user account does not belong to the required security group, they know the credentials are correct. Result is they start looking for other ways to get in, as they now have a valid user account.
The best way to get around this is to not have a dedicated url for authentication, like
aaa.domain.com or
auth.domain.com if possible. If you use the application url like
app.domain.com for authentication, the service request for help should know what to check when a call comes in as they only have to ask which url was used.